2026-08-04 · view entry permalink →
CrowdStrike 2026 Threat Hunting Report: 88% of public-PoC exploitation landed inside 48 hours, and npm accounted for 87% of software-registry threats
CrowdStrike's Counter Adversary Operations team published its annual Threat Hunting Report on 2026-08-03, drawing on OverWatch managed-hunting and CrowdStrike Intelligence telemetry from what it describes only as "the past year" (CrowdStrike, 2026-08-03); reporting on the release puts that window at the 12 months to 30 June 2026 (SiliconANGLE, 2026-08-03). Only a few of its findings change a defender's decisions; those are the ones worth carrying.
The one that does most work is the exploitation-velocity measurement: "From January through June 2026, 88% of CrowdStrike-observed exploitation of vulnerabilities with a public PoC was conducted within 48 hours of the PoC's release." The named cases go faster still. China-nexus VAULT PANDA and GENESIS PANDA launched deliberate attacks within 24 hours of the public disclosure of a critical web-application flaw, and after the React2Shell disclosure OverWatch worked 800+ hunting leads across more than 80 victims in four days. For a Linux local privilege-escalation flaw disclosed on 29 April with a researcher PoC released the same day, OverWatch saw widespread exploit deployment the following day — roughly 94% of first-day events matching public PoC testing behaviour — and for the Belarus-nexus actor UMBRAL BISON, "They uncovered Belarus-nexus activity in just over 20 hours after public disclosure." CrowdStrike's own read is that this pattern predates frontier AI models but that those models are likely to compress the timeline further by accelerating vulnerability discovery and exploit development.
The practical consequence is a prioritisation input rather than a task: for an internet-reachable component, the arrival of a public proof-of-concept is the trigger, and waiting for a KEV listing or the next scheduled maintenance window puts the decision after the exploitation rather than before it. That reframing bites hardest on the exposure classes this constituency runs at the perimeter — the edge appliances, management planes and web applications that need no user interaction to reach.
On the software supply chain, the concentration figure is the useful one: "87% of identified software registry threats in the first half of 2026 involved npm packages", which CrowdStrike attributes to JavaScript's dependency-chain scale and automatic install scripts. The named activity adds tradecraft detail on a cluster this store already tracks under the name Sapphire Sleet, one of whose recorded aliases is CrowdStrike's STARDUST CHOLLIMA: the DPRK-nexus actor used stolen maintainer credentials in March 2026 to compromise the axios npm package and deliver platform-specific variants of its ZshBucket malware, and in June 2026 injected a malicious npm package as a dependency into at least 131 Mastra AI framework packages — which CrowdStrike reads as trusted AI building blocks becoming supply-chain targets. A separate financially motivated actor, ALTERED SPIDER, compromised more than 300 software dependencies in one day, harvested credentials and pivoted into cloud environments.
Three identity and AI observations complete the picture without carrying separate action, because the underlying tradecraft is already covered in this store's operational entries. Vishing intrusions in H1 2026 doubled against H2 2025, with CrowdStrike recording one case in which an eCrime operator moved from account takeover to SaaS data theft in under five minutes. Monthly device-code phishing attempts rose 15x over six months. And on the defender's side of the ledger, "AI agent-triggered detection leads now surface 2.5x more threat leads than manually driven activity", which CrowdStrike frames as making it harder to separate malicious activity from expected AI-driven behaviour — a triage-volume problem rather than an attacker capability gain. One LLMjacking campaign generated nearly 200,000 API requests in two minutes against a hijacked service.
From January through June 2026, 88% of CrowdStrike-observed exploitation of vulnerabilities with a public PoC was conducted within 48 hours of the PoC’s release.
They uncovered Belarus-nexus activity in just over 20 hours after public disclosure.
87% of identified software registry threats in the first half of 2026 involved npm packages.
Builds on: 2026-07-30/amazon-dprk-attribution-npm-typo-crypto-rehearsal · 2026-05-09/cve-2026-31431-copy-fail-cisa-kev-deadline-2026-05-15-approa